<!DOCTYPE html>
<html lang="en">

<head>
    <meta charset="UTF-8">
    <meta http-equiv="X-UA-Compatible" content="IE=edge">
    <meta name="viewport" content="width=device-width, initial-scale=1.0">
    <title>Document</title>
    <script src="https://cdn.jsdelivr.net/npm/vue@2/dist/vue.js"></script>
</head>

<body>
    <div id="app">
        <div>{{message}}</div>
         
        <!-- v-text是vue第一个指令 -->
        <div v-text='message'>

        </div>
        <!-- v-html  innerHTML -->

        <div v-text='img1'>

        </div>
        <!-- 用v-text就解决了XSS攻击的危害 -->
        <div v-html='img1'>

        </div>
    </div>


    <script>
   
        var app = new Vue({
            el: '#app',
            data: {
                message: 'Hello Vue22222!',
                img1:"<img src='https://ftp.bmp.ovh/i.jpg' onerror='alert(444444)'>"
            }
        })

        console.log('app', app)

    </script>
</body>

</html>